Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.76% | — | Jetbrains Youtrack | 2/10/2019 | 17/6/2026 | JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page. | |
| Modificada | Media (4.3) | 0.98% | — | Jetbrains Youtrack | 2/10/2019 | 17/6/2026 | JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names. | |
| Modificada | Media (6.1) | 1.0% | — | Jetbrains Youtrack | 1/10/2019 | 17/6/2026 | JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere. | |
| Modificada | Media (6.1) | 0.89% | — | Jetbrains Youtrack | 1/10/2019 | 17/6/2026 | JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser. | |
| Modificada | Media (6.1) | 1.1% | — | Jetbrains Youtrack | 1/10/2019 | 17/6/2026 | JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles. | |
| Modificada | Crítica (9.8) | 1.8% | — | Jetbrains Youtrack | 3/7/2019 | 17/6/2026 | An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168. | |
| Modificada | Crítica (9.8) | 2.0% | — | Jetbrains Youtrack | 3/7/2019 | 17/6/2026 | Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168. | |
| Modificada | Crítica (9.8) | 1.9% | — | Jetbrains Youtrack | 3/7/2019 | 17/6/2026 | An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168. | |
| Modificada | Alta (8.8) | 0.75% | — | Jetbrains Youtrack | 3/7/2019 | 17/6/2026 | A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852. | |
| Modificada | Crítica (9.8) | 2.1% | — | Jetbrains Youtrack | 3/7/2019 | 17/6/2026 | A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168. | |
| Modificada | Crítica (9.8) | 2.2% | — | Jetbrains Youtrack Integration | 3/7/2019 | 17/6/2026 | In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely. | |
| Modificada | Alta (8.8) | 1.8% | — | Jenkins Youtrack-plugin | 4/4/2019 | 17/6/2026 | Jenkins youtrack-plugin Plugin 0.7.1 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. |